As enterprises move from generative AI assistants to agents that can take action, security teams are being forced to rethink what authorisation means. F5’s announced Workforce AI Security product is built around a useful phrase for the problem: 'borrowed authority'.
An AI agent may be able to access an enterprise system, retrieve data or invoke a tool because it is operating under permissions granted to a human user. The user may be properly authenticated, but that does not automatically mean every action generated by the agent should be permitted.
F5 says Workforce AI Security is due to begin general availability in October 2026. The company says that, upon availability, expected capabilities include inspecting and classifying agent tool calls - including calls through Model Context Protocol connections - and applying policy based on identity, access risk and sensitive-data exposure.

The Model Context Protocol, or MCP, is an open protocol for connecting AI applications and agents to external tools and data sources. Its usefulness is also what creates the security challenge. Once an agent can reach enterprise services through tools, prompt-level controls are no longer enough. Security policy has to follow the action.
The core question becomes more specific than 'is this user authenticated?'. It is closer to: is this agent authorised to perform this particular action, using this user’s authority, against this system, with this data, at this moment? That requires context from identity systems, tool permissions, data classification and runtime security controls.
The borrowed-authority problem also illustrates why agent governance and cyber security are converging. An organisation needs an inventory of the agents it has allowed into production, a way to associate them with owners, clear limits on what they can do and evidence of the actions they take. Without those elements, an AI governance policy can describe acceptable behaviour without providing a mechanism to enforce it.

For regulated businesses, the issue becomes even more important when agents touch customer data, financial transactions, claims, trading systems or other sensitive workflows. A legitimate user can accidentally or deliberately instruct an agent to do something that exceeds the intended purpose of their access. The control point therefore needs to consider the action, not just the identity behind the session.
F5’s announcement is part of a broader market shift toward runtime controls for agentic AI. The strategic question for enterprises is how these new controls will integrate with existing identity, data security and application security tools rather than becoming another standalone layer that security teams have to manage separately.
